Coldcard Firmware Seed Vulnerability Exploit
The March 2021 Coldcard firmware flaw that routed seed generation to predictable software randomization instead of hardware randomization has created a bounded and reproducible key space that attackers can exploit offline at scale
Too little corroboration in the last 3 days to call a trend (6 articles). Watching for it to gain traction.
Still mostly niche and specialist coverage — not yet picked up broadly by mainstream press.
"In late July 2026, Bitcoin hardware wallet maker Coinkite disclosed that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate seed phrases from a much smaller pool of possible values than intended. That reduced the randomness protecting users' private keys, making them vulnerable to attackers who could guess them—or use AI to guess them much more quickly than they otherwise could manually."
"The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip's hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device."
"An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite."
"Block says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data."
"Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Coinkite tells owners with exposed seeds to generate a new one on patched firmware and move their coins."
"Novak also said Coinkite released a hotfix intended to remove the software fallback path. However, he warned that installing the fix does not retroactively protect seeds that were generated using vulnerable firmware. In practical terms, Novak advised users who created seeds on the vulnerable firmware to move their funds to a new seed."